Deployment Architecture

how to know and delete old indexed log files in hard disk?

shariinPH
Contributor

Hi all
I want to know what are the old indexed log file and at the same time delete those log files on my hard disk
Pls help me with this.

Thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi shariinPH,

If you haven't set any coldToFrozenScript in your indexes.conf your old events will not be archived http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Automatearchiving

That said, if you're using all default settings for your indexes, Splunk will delete any old events for you.
Check the docs for more details on that http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Setaretirementandarchivingpolicy

Hope that helps ...

cheers, MuS

shariinPH
Contributor

Thanks @MuS !!:)

0 Karma

MuS
SplunkTrust
SplunkTrust

If this answers your question, please accept it - thx 🙂

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...